IEC TR 62351-13:2016 PDF
Power systems management and associated information exchange - Data and communications security - Part 13: Guidelines on security topics to be covered in standards and specifications
Power systems management and associated information exchange - Data and communications security - Part 13: Guidelines on security topics to be covered in standards and specifications
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 34
- Дата публикации:
- 9 августа 2016 г.
- Издание:
- IEC TR 62351 edition 1 version 1
- ICS:
- 33.200
IEC TR 62351-13:2016(E) provides guidelines on what security topics could or should be covered in standards and specifications (IEC or otherwise) that are to be used in the power industry, and the audience is therefore the developers of standards and specifications. These guidelines cannot be prescriptive for every standard, since individual standards and specifications may legitimately have very different focuses, but it should be expected that the combination of such standards and specifications used in any implementation should cover these security topics. These guidelines are therefore to be used as a checklist for the combination of standards and specifications used in implementations of systems.
Abstract
Overview
IEC TR 62351-13:2016 - part of the IEC 62351 series on power systems data and communications security - provides guidelines for security topics that should be covered in standards and specifications used in the power industry. It is aimed at standards and specification developers, not at prescribing implementation-level security controls. The report frames a checklist approach so that the combination of standards and specifications used in any system implementation collectively addresses essential cybersecurity topics.
Key Topics and Requirements
The Technical Report organizes guidance across four primary areas (summarized from its clauses):
-
Security requirements for users and applications (Clause 5)
- Risk assessment, security policies, roles and authorization
- User-focused procedures and accountability (policy, training, access control)
-
ICT cryptographic techniques (Clause 6)
- Best practices for specifying cryptography (selection, lifecycle, and applicability)
- Key management (including public-key approaches), multicast/group key considerations
- Device and platform integrity, secure network configuration, Internet and wireless cryptography
- Network and system management, defence‑in‑depth, security testing and interoperability
-
Engineering design and configuration management for grid resilience (Clause 7)
- Integration of cyber security into system engineering and planning
- Design strategies for resilience, monitoring, centralized analysis, testing, and training
-
Correlation with information exchange standards and OSI layers (Clause 8)
- Mapping security requirements to OSI layers and to relevant IEC communications standards
- Guidance on ensuring complementary standards collectively mitigate threats
The report emphasizes that some standards should focus on policy/organizational controls while others implement technical (“bits and bytes”) measures - together they must form a complete security posture.
Practical Applications and Intended Users
IEC TR 62351-13 is a practical reference and checklist for:
- Standards committees and specification authors drafting power‑industry standards
- Utilities, system integrators and equipment vendors validating that combined standards cover required security topics
- Security architects and compliance teams mapping requirements across protocols, devices and organizational practices
- Certification and regulatory bodies assessing completeness of security coverage in deployments
Use cases include scoping new standards, reviewing existing specifications for gaps (policy, cryptography, engineering), and aligning security across the OSI stack.
Related Standards and Context
- Part of the IEC 62351 series (data and communications security for power systems)
- References IEC TS 62351-2 (glossary) and maps security needs to IEC communications standards and OSI layers
- Intended as guidance, not prescriptive implementation rules - best used as a checklist to ensure comprehensive coverage of cybersecurity topics across standards.
Технические детали
- Технический комитет
- TC 57 - Power systems management and associated information exchange
- SKU
- IEC TR 62351-13:2016
Похожие стандарты
Упомянутые в описании и другие стандарты IEC
IEC 62351-8:2026
ДействующийPower systems management and associated information exchange - Data and communications security - Part 8: Rol…
Overview IEC 62351-8:2026 is an international standard developed by the International Electrotechnical Commission (IEC) as part of the IEC 62351 series, focusing on data and communications security i…
IEC 60050-161:1990/AMD2:1998
ДействующийAmendment 2 - International Electrotechnical Vocabulary (IEV) - Part 161: Electromagnetic compatibility
IEC 60050-161:1990/AMD2:1998 – Electromagnetic Compatibility Vocabulary Amendment ### Overview The IEC 60050-161:1990/AMD2:1998 is the second amendment to the International Electrotechnical Vocabular…